About the job
Join us as the Associate Director of Cyber Security, where you will spearhead our cybersecurity strategy and governance. This pivotal role involves overseeing risk management and operational security functions to protect our IT infrastructure, applications, and data across the wholesale business. You will ensure that our cybersecurity initiatives are in harmony with business objectives while maintaining compliance with regulatory standards and best practices to mitigate risks effectively.
Key Responsibilities:
1. IT Governance & Risk Program Management
- Formulate and enforce cybersecurity policies, standards, and guidelines that align with the business's requirements and regulatory mandates.
- Lead comprehensive risk assessments and implement strategies to bolster cybersecurity resilience across the enterprise.
- Establish a robust cybersecurity governance framework that guarantees compliance with standards such as ISO 27001, NIST, GDPR, and PDPA.
- Manage third-party security risks through vendor security evaluations and ensure contractual compliance.
2. Security Architecture & Engineering
- Design and implement secure architectures that safeguard the organization’s IT assets and digital infrastructure.
- Collaborate with IT teams to integrate security measures into cloud environments, network systems, and enterprise applications.
- Oversee vulnerability management, conduct penetration testing, and enforce secure software development lifecycle (SDLC) practices.
3. Identity & Access Management (IAM)
- Develop and oversee IAM strategies that ensure the implementation of appropriate user access controls and authentication mechanisms.
- Manage Privileged Access Management (PAM) and Single Sign-On (SSO) solutions to enhance security posture.
- Enforce role-based access control (RBAC) and the principle of least privilege across all systems.
4. Security Operations Center (SOC) & Cyber Defense
- Lead the Security Operations Center (SOC) to monitor, detect, and respond to cybersecurity threats in real-time.
- Manage incident response, forensic investigations, and cyber threat intelligence initiatives.
- Implement advanced security analytics, Security Information and Event Management (SIEM), and threat-hunting capabilities.
- Develop and execute cybersecurity awareness training programs for employees.
